ZeroHour

CVE-2022-25329

CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.

Vendors
trendmicro
Products
serverprotect, serverprotect for network appliance filer, serverprotect for storage
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.